CVE-2018-9193: High severity fortinet forticlient ssl vpn vulnerability
A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the parsing of the file.
Other sources
A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into an exploit chain, which allows a user to gain system privileges on Microsoft Windows.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-9193?
CVE-2018-9193 is a local privilege escalation vulnerability in Fortinet FortiClient for Windows 6.0.4 and earlier.
How does CVE-2018-9193 impact the affected software?
CVE-2018-9193 allows an attacker to execute unauthorized code or commands on the affected system.
What is the severity of CVE-2018-9193?
CVE-2018-9193 has a severity score of 7.8, which indicates a high severity vulnerability.
How can I fix CVE-2018-9193?
To fix CVE-2018-9193, Fortinet FortiClient for Windows should be updated to version 6.0.5 or later.
Where can I find more information about CVE-2018-9193?
More information about CVE-2018-9193 can be found on the FortiGuard Advisory page: https://fortiguard.com/advisory/FG-IR-18-108